// For flags

CVE-2008-1693

xpdf: embedded font vulnerability

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

La función CairoFont::create en CairoFontEngine.cc de Poppler, posiblemente anterior a 0.8.0, como se usa en Xpdf, Evince, ePDFview, KWord y otras aplicaciones, no maneja correctamente fuentes embebidas en archivos PDF, lo que permite a atacantes remotos ejecutar código de su elección a través de un objeto fuente manipulado, relacionado con referenciar un puntero de una función asociado con el tipo de este objeto fuente.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-04-08 CVE Reserved
  • 2008-04-17 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-20 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
References (36)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
<= 0.7.3
Search vendor "Poppler" for product "Poppler" and version " <= 0.7.3"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.1
Search vendor "Poppler" for product "Poppler" and version "0.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.1.1
Search vendor "Poppler" for product "Poppler" and version "0.1.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.1.2
Search vendor "Poppler" for product "Poppler" and version "0.1.2"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.2.0
Search vendor "Poppler" for product "Poppler" and version "0.2.0"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.0
Search vendor "Poppler" for product "Poppler" and version "0.3.0"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.1
Search vendor "Poppler" for product "Poppler" and version "0.3.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.2
Search vendor "Poppler" for product "Poppler" and version "0.3.2"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.3.3
Search vendor "Poppler" for product "Poppler" and version "0.3.3"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.0
Search vendor "Poppler" for product "Poppler" and version "0.4.0"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.1
Search vendor "Poppler" for product "Poppler" and version "0.4.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.2
Search vendor "Poppler" for product "Poppler" and version "0.4.2"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.3
Search vendor "Poppler" for product "Poppler" and version "0.4.3"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.4.4
Search vendor "Poppler" for product "Poppler" and version "0.4.4"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.0
Search vendor "Poppler" for product "Poppler" and version "0.5.0"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.1
Search vendor "Poppler" for product "Poppler" and version "0.5.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.2
Search vendor "Poppler" for product "Poppler" and version "0.5.2"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.3
Search vendor "Poppler" for product "Poppler" and version "0.5.3"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.4
Search vendor "Poppler" for product "Poppler" and version "0.5.4"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.9
Search vendor "Poppler" for product "Poppler" and version "0.5.9"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.5.91
Search vendor "Poppler" for product "Poppler" and version "0.5.91"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.0
Search vendor "Poppler" for product "Poppler" and version "0.6.0"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.1
Search vendor "Poppler" for product "Poppler" and version "0.6.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.2
Search vendor "Poppler" for product "Poppler" and version "0.6.2"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.3
Search vendor "Poppler" for product "Poppler" and version "0.6.3"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.6.4
Search vendor "Poppler" for product "Poppler" and version "0.6.4"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.0
Search vendor "Poppler" for product "Poppler" and version "0.7.0"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.1
Search vendor "Poppler" for product "Poppler" and version "0.7.1"
-
Affected
Poppler
Search vendor "Poppler"
Poppler
Search vendor "Poppler" for product "Poppler"
0.7.2
Search vendor "Poppler" for product "Poppler" and version "0.7.2"
-
Affected